Data Processing Addendum
Version 2.0Effective September 1, 2026Current policy
On this page
ChemCal Pro Data Processing Addendum
Version 2.0 | Effective date: September 1, 2026
Application of this version. This version applies when made available and incorporated into the customer agreement through the applicable notice and acceptance process. The effective date above does not establish earlier acceptance or change rights that have already accrued.
---
1. What this addendum is and when it applies
1.1 This Data Processing Addendum (the "DPA") forms part of the ChemCal Pro Terms of Service, or of another written agreement between ChemCal Pro LLC ("ChemCal Pro") and the customer organization ("Customer") for the ChemCal Pro service (together, the "Agreement"). Terms defined in the Agreement have the same meaning here.
1.2 This DPA applies where and to the extent ChemCal Pro processes personal data on Customer's behalf and on Customer's instructions in providing the Service.
1.3 This DPA does not apply to personal data for which ChemCal Pro determines the purposes and means itself. That processing is described in the Privacy Notice and is listed in Section 2.4.
1.4 Precedence. As to the processing of Customer Personal Data, this DPA prevails over a conflicting term in the Agreement. A data-transfer instrument the parties have separately completed and executed prevails over this DPA to the extent necessary for the transfer it covers. The Privacy Notice does not override this DPA.
---
2. Definitions and roles
2.1 "Applicable Data Protection Law" means privacy and data-protection law that applies to the processing of Customer Personal Data under this DPA, which may include United States federal and state privacy law, Canadian federal and provincial privacy law, UK data-protection law, Australian privacy law, and the EU General Data Protection Regulation, in each case only where and to the extent it actually applies to that processing.
2.2 "Customer Personal Data" means personal data that ChemCal Pro processes on Customer's behalf through the Service.
2.3 "Controller," "processor," "data subject," "personal data," "process" and "supervisory authority" have the meanings given by Applicable Data Protection Law. "Business," "consumer," "service provider," "sell" and "share" have the meanings given by applicable United States state privacy law.
2.4 Roles. For Customer Personal Data, Customer is the controller or business and ChemCal Pro is the processor or service provider. ChemCal Pro is an independent controller for a limited set of its own purposes: contracting and account administration; billing, tax and accounting; fraud prevention and service security; direct service communications; support and meeting correspondence; legal compliance; and the establishment or defence of legal claims.
2.5 "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Customer Personal Data processed by ChemCal Pro. It does not include an unsuccessful attempt that does not compromise Customer Personal Data, such as a blocked scan or a failed sign-in.
2.6 "Subprocessor" means a third party ChemCal Pro engages to process Customer Personal Data on Customer's behalf.
2.7 Each party will comply with Applicable Data Protection Law as it applies to that party's own role. Entering this DPA does not transfer Customer's own statutory obligations to ChemCal Pro, and it does not relieve Customer of its duties as controller — including choosing an appropriate processor, giving lawful instructions, providing required notices, and responding to data subjects.
---
3. Customer's instructions and responsibilities
3.1 What counts as an instruction. Customer's documented instructions are: the Agreement; this DPA; Customer's configuration and use of the Service; and documented instructions given to ChemCal Pro by an active Company Admin. ChemCal Pro will process Customer Personal Data only on those instructions, including for any transfer, unless law requires otherwise — in which case ChemCal Pro will tell Customer before processing, if the law permits.
3.2 Customer's responsibilities. Customer is responsible for the lawfulness, fairness, accuracy and quality of Customer Personal Data and of its instructions, including any required notices, lawful bases, consents, employment-law obligations and the rights of its Authorized Users.
3.3 Data minimisation by Customer. Customer will not instruct ChemCal Pro to process personal data unnecessary to the Service, and in particular will not use the Service to store its own end customers' identities, service addresses, route or job data, or pesticide-application records. Where the Service provides a feature for a category of personal data — for example member profile photographs and credential records — Customer will use that feature only for its intended workforce-management purpose and will not put more into it than that purpose requires.
3.4 Unlawful instructions. If, in ChemCal Pro's opinion, an instruction infringes Applicable Data Protection Law, ChemCal Pro will inform Customer immediately, and may suspend the affected processing until the instruction is resolved. ChemCal Pro will do so unless the law prevents it from telling Customer.
3.5 Contacts. Customer will keep a current security and privacy contact on its account and will tell ChemCal Pro promptly if it suspects a compromise involving its accounts.
---
4. ChemCal Pro's core processing obligations
ChemCal Pro will:
- process Customer Personal Data only as described in Section 3.1 and in Annex 1;
- not sell or share Customer Personal Data, and not use it for its own advertising or to build or train a product, model or dataset for third parties;
- keep the confidentiality obligations in Section 5;
- maintain the security measures in Section 6 and Annex 2;
- respect the subprocessor conditions in Section 7;
- assist Customer as set out in Sections 8, 9 and 11;
- make available the information described in Section 13; and
- return or delete Customer Personal Data as set out in Section 12.
---
5. Confidentiality and personnel
5.1 ChemCal Pro will ensure that people authorized to process Customer Personal Data are bound by an appropriate contractual or statutory duty of confidentiality.
5.2 Access will be limited to people who need it to provide, secure, maintain, troubleshoot or support the Service, to comply with law, or to act on an authorized request, and will be limited to what those tasks require.
5.3 ChemCal Pro will give personnel with access appropriate privacy and security direction.
---
6. Security
6.1 The obligation. Taking account of the state of the art, the cost of implementation, the nature, scope, context and purposes of the processing, and the risk to individuals, ChemCal Pro will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against a Security Incident. The measures in place at the date of this DPA are described in Annex 2.
6.2 What this obligation is not. ChemCal Pro does not warrant that the Service or its providers cannot be compromised, that data cannot be lost, or that any particular availability or response level will be achieved. This DPA does not create a service-level commitment. Security is an obligation of appropriate care, not a guarantee of outcome.
6.3 Changes. ChemCal Pro may change its security measures, provided the change does not materially reduce the overall level of protection for Customer Personal Data.
6.4 Customer's part. Customer is responsible for configuring roles correctly, protecting credentials and devices, removing users promptly, reviewing what its people upload, and using the Service's security features appropriately.
6.5 No certification is claimed. ChemCal Pro does not hold, and does not represent that it holds, a SOC 2 report, an ISO/IEC 27001 certification, or any comparable independent audit or certification. If that changes, ChemCal Pro will say so specifically rather than by implication.
---
7. Subprocessors
7.1 General authorization. Customer gives ChemCal Pro general written authorization to engage the subprocessors identified in Section 4 (Subprocessors) of the Subprocessors and Service Providers registry, published on ChemCal Pro's legal pages. Section 4 of that registry is Annex 3 to this DPA.
7.2 Flow-down. ChemCal Pro will impose on each subprocessor, by written contract, the same substantive data-protection obligations that apply to ChemCal Pro under this DPA, so far as they are applicable to that subprocessor's processing, including in particular sufficient guarantees as to appropriate technical and organizational security measures. ChemCal Pro remains fully liable to Customer for a subprocessor's performance of those obligations to the extent Applicable Data Protection Law requires.
7.3 Responsibility. Engaging a subprocessor does not reduce ChemCal Pro's obligations to Customer under this DPA.
7.4 Notice of change. ChemCal Pro will publish an updated, dated registry before a new subprocessor begins processing Customer Personal Data, and will give at least 30 days' notice of a material new or replacement subprocessor by updating the registry and notifying the account contact of record. Where an emergency replacement is reasonably necessary to protect the Service or to comply with law, ChemCal Pro will act as promptly as it can and will notify Customer as soon as practicable.
7.5 Objection. Customer may object within the notice period on reasonable, documented data-protection grounds. The parties will work in good faith to address the objection. If ChemCal Pro cannot offer a commercially reasonable alternative, Customer may terminate the affected part of the Service before the subprocessor begins processing Customer Personal Data, and ChemCal Pro will refund prepaid fees for the terminated part covering the period after termination. That is Customer's exclusive remedy for a properly raised subprocessor objection, without limiting a right that cannot lawfully be excluded.
7.6 No subscription list is required. Customer does not need to subscribe to receive notices under this section. The registry is published and dated, and notice goes to the account contact of record.
---
8. Data subject requests
8.1 Taking account of the nature of the processing, ChemCal Pro will provide reasonable assistance — through the Service's own functionality where it exists, and otherwise by reasonable means — to help Customer respond to a verified request from a data subject to exercise a right.
8.2 If ChemCal Pro receives a request that relates primarily to Customer Personal Data, ChemCal Pro will tell the requester to contact Customer where that is appropriate, will inform Customer, and will not respond substantively except on Customer's instruction or where the law requires ChemCal Pro to respond.
8.3 Customer decides whether and how to fulfil a request. ChemCal Pro may charge a reasonable fee for extraordinary assistance that the Service does not include, after telling Customer in advance, unless the law requires the assistance without charge.
---
9. Assessments, consultations and compliance assistance
Taking account of the nature of the processing and the information available to it, ChemCal Pro will give Customer reasonable assistance with Customer's obligations relating to security, Security Incident notification, data-protection impact assessments, and prior consultation with a supervisory authority. Extraordinary assistance may attract a reasonable fee after advance notice.
---
10. Government and other legal requests
10.1 ChemCal Pro will review a request for Customer Personal Data and disclose only where it reasonably believes disclosure is legally required.
10.2 Where legally permitted, ChemCal Pro will tell Customer before disclosing and give Customer reasonable information so that Customer can seek protective relief.
10.3 ChemCal Pro will use reasonable efforts to challenge a request that appears overbroad or unlawful, where that is appropriate in the circumstances.
---
11. Security Incident notification
11.1 The trigger is awareness, not certainty. ChemCal Pro will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. ChemCal Pro will not wait for an investigation to be completed, for the cause to be confirmed, or for the full scope to be known before notifying.
11.2 Earlier deadlines apply where the law sets one. Where Applicable Data Protection Law, or a law applicable to ChemCal Pro as a person who maintains data on Customer's behalf, requires notification within a shorter or earlier period — including a requirement to notify the owner or licence holder of the data immediately after discovery — ChemCal Pro will meet that shorter or earlier requirement. Nothing in this DPA creates a longer period or a safe harbour.
11.3 What the notice contains. ChemCal Pro will provide the information reasonably available to it at the time, which may include the nature of the incident, the categories and approximate volume of data and individuals affected, the likely consequences, the measures taken or proposed, and a contact point. Information will be provided in phases as it becomes available.
11.4 What ChemCal Pro will do. ChemCal Pro will take reasonable steps to contain, investigate, mitigate and remediate the incident, will preserve relevant evidence, and will cooperate reasonably with Customer's own legally required response.
11.5 Who notifies whom. ChemCal Pro's notice to Customer is not an admission of fault or liability. Customer is responsible for any notification it must make to individuals or regulators, unless the law places that duty directly on ChemCal Pro.
---
12. Return, deletion, retention and backups
12.1 During the term, Customer may access Customer Personal Data through the Service and use available export functions, or request a copy through an authenticated support request. This does not promise that every category has a self-service bulk-export screen.
12.2 On termination, or on Customer's authenticated written request, ChemCal Pro will return or delete Customer Personal Data — at Customer's choice. ChemCal Pro will do so after the provision of the Service has ended, except to the extent applicable law requires ChemCal Pro to store the data. Backup copies are handled under Section 12.4.
12.3 What may and may not delay this. ChemCal Pro may verify the identity and authority of the person making the request, and may preserve data that is subject to a legal hold or to a dispute the parties have preserved. Technical difficulty, inconvenience, or the design of ChemCal Pro's systems is not a right to refuse or indefinitely postpone return or deletion. Where a step takes time to complete, ChemCal Pro will tell Customer what remains, why, and when it will be done.
12.4 Backups — beyond use, then deleted. Customer Personal Data may remain in ChemCal Pro's own snapshot copies and in its providers' backups after deletion from the live Service. For as long as it does:
- it is put beyond use — it is not restored to, or used for, any ordinary business purpose, is access-restricted, and is used only to restore service, investigate a security incident, or meet a legal obligation;
- if a backup is restored for any reason, ChemCal Pro will re-apply the deletion to the restored data without undue delay; and
- it is deleted when the applicable backup cycle expires.
12.5 The retention schedule this section depends on. ChemCal Pro will maintain and operate a documented retention and disposal schedule for its own snapshot copies, and will make its current terms available to Customer on request under Section 13.
12.6 The narrow set of records ChemCal Pro keeps in its own right — and the boundary. Separately from the processor data addressed in Sections 12.2 to 12.4, ChemCal Pro keeps a small, defined set of records as an independent controller, on its own lawful basis:
| Record | Why | Fields kept |
|---|---|---|
| Legal acceptance evidence | To show that a contract was formed and by whom | The minimum described in Section 12.7 |
| Billing, tax and accounting records | Legal obligation, and accurate commercial records | Transaction and subscription records |
| Fraud-prevention and security records | Protecting the Service and its users | Security event records |
| Records preserved for a specific dispute or legal hold | Establishing or defending a legal claim | Only what the matter requires |
Each is limited to the minimum fields necessary for its stated purpose, is access-restricted, and is used only for that purpose. Each is kept only while that purpose still applies and is reviewed against the schedule in Section 12.5.
This section is not a general permission to keep processor data. In particular, "audit integrity" is not a basis for preserving a Customer's records generally. Product records, document records, calculator definitions, verification history and publication records are Customer Personal Data or Customer Content held as processor, and are returned or deleted under Section 12.2 at Customer's choice — not retained under this Section 12.6.
12.7 Legal acceptance evidence, stated specifically. The record that a particular version of the Agreement was accepted — the organization's name and reference, the accepting administrator's verified email address and their role at the time, the document version and content fingerprint, and the date and time — is retained as contract-formation evidence, including after that individual's identity is deleted from the Service. It is kept for as long as a claim relating to the agreement could reasonably be brought or defended, and no longer as of right. Customer should make its Authorized Users aware of this; the Privacy Notice states it to individuals.
12.8 De-identified data. ChemCal Pro may retain data that has been irreversibly de-identified and can no longer reasonably be attributed to a person or to Customer.
---
13. Audits and information
13.1 ChemCal Pro will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA.
13.2 Customer will first use ChemCal Pro's current security documentation, policies, completed questionnaires, and any independent reports ChemCal Pro can lawfully provide.
13.3 No more than once in any twelve-month period, and additionally after a substantiated Security Incident affecting Customer or on a supervisory authority's requirement, Customer may request a reasonable remote audit relating to Customer Personal Data.
13.4 An on-site audit is available only where a supervisory authority requires it, or where documentation and remote review cannot reasonably resolve a substantiated material concern. It must take place during normal business hours, on reasonable advance notice, under confidentiality obligations, without access to another customer's information, and without unreasonable disruption.
13.5 Customer bears its own audit costs, and ChemCal Pro's reasonable costs for extraordinary assistance, unless the audit identifies a material breach of this DPA by ChemCal Pro.
13.6 These limits do not override the law. Nothing in this Section 13 — the frequency limit, the documentation-first step, the on-site conditions or the cost allocation — prevents or delays access, an inspection, an audit or assistance that Applicable Data Protection Law requires ChemCal Pro to allow or provide, including where a supervisory authority requires it. Those limits do not require ChemCal Pro to give access to another customer's information, to personal data it does not process for Customer, or to its own security credentials or trade secrets.
---
14. United States state privacy terms
To the extent applicable United States state privacy law treats ChemCal Pro as a service provider or processor for Customer Personal Data:
- ChemCal Pro processes Customer Personal Data only for the limited and specified business purposes set out in the Agreement, this DPA and Customer's instructions;
- ChemCal Pro will not sell or share Customer Personal Data, will not retain, use or disclose it outside the direct business relationship or for any purpose other than those specified, and will not combine it with personal data from another source, except as that law permits and as necessary to provide or secure the Service;
- ChemCal Pro will comply with the obligations that law places on a service provider or processor and will provide the same level of protection it requires;
- Customer may take reasonable and appropriate steps to confirm that ChemCal Pro uses Customer Personal Data consistently with Customer's obligations, and may require ChemCal Pro to stop and remediate unauthorized processing; and
- ChemCal Pro will tell Customer if it determines that it can no longer meet those obligations.
---
15. International transfers
15.1 Where the Service is provided from. ChemCal Pro operates from the United States. Provider processing locations and geographies are described in the Subprocessors and Service Providers registry to the extent verified; ChemCal Pro makes no exclusive data-residency commitment.
15.2 Establish the applicable lawful transfer route. Where Applicable Data Protection Law restricts a transfer of Customer Personal Data, the parties must establish the applicable lawful route before the transfer. An applicable adequacy mechanism, an appropriate safeguard and a recognised exception are different routes. Where the route requires a contractual instrument, the correct official instrument must be properly completed and executed, with any required assessment and supplementary measures, before the transfer takes place.
15.3 What this DPA does not do. This DPA does not incorporate, execute or complete a standard transfer instrument, and does not establish an adequacy mechanism or exception. ChemCal Pro will identify the route actually relied on and retain supporting evidence rather than treating this DPA as proof that a restricted transfer is permitted.
15.4 Transfer documentation. Where a contractual transfer instrument is required, the parties will document the applicable parties and roles, processing particulars, onward transfers, and required transfer assessment. Preparatory documentation does not itself execute a transfer instrument or establish a lawful transfer route.
15.5 Cooperation. The parties will cooperate reasonably on a transfer risk assessment and on any supplementary measures required. If a mechanism the parties are using ceases to be valid, they will use an available lawful alternative; if none is reasonably available, ChemCal Pro may suspend the affected transfer.
---
16. Liability
16.1 Liability arising under or in connection with this DPA — including liability arising from a Security Incident, loss, corruption, or unauthorized access to, use of or disclosure of Customer Personal Data, and liability arising from an assistance obligation — is subject to the Limitation of liability section of the Terms of Service and the exceptions stated there. For Customer's claims subject to those contractual limits, this includes the protections for Protected Persons and the one shared aggregate cap for ChemCal Pro and those persons, together with their express enforcement rights under Section 23.11 of the Terms. This DPA does not create a separate or enhanced contractual cap or make an owner or other Protected Person personally responsible for ChemCal Pro's processor obligations.
16.2 Nothing in this Section 16 limits liability that Applicable Data Protection Law does not permit to be limited, or a data subject's rights against either party or a Protected Person under that law. Rights and remedies under an applicable data-transfer instrument remain unaffected to the extent that instrument requires.
---
17. Term and changes
17.1 This DPA applies for as long as ChemCal Pro processes Customer Personal Data, and the provisions that must survive will survive.
17.2 ChemCal Pro may update this DPA to reflect legal or operational change, but will not materially reduce the protection it provides without reasonable notice. A material change may require acceptance by an authorized Company Admin.
---
Annex 1 — Details of processing
Subject matter. Hosting and operation of the ChemCal Pro service for Customer.
Duration. The term of the Agreement, plus the limited periods described in Section 12.
Nature of the processing. Collection, recording, organization, structuring, storage, retrieval, consultation, use, transmission, display, restriction, support access, backup, deletion and de-identification.
Including one transient operation worth naming: when an Authorized User runs a product-bound Customer Calculator, the values entered are transmitted to ChemCal Pro's servers, the locked calculator definition is loaded from Customer's own records, the calculation is evaluated server-side under that user's session, and the result is returned. No record of the inputs or the result is persisted. General measurement tools that are not bound to a product may run entirely in the browser.
Purpose. Account and organization administration; product record management; storage and versioning of Label and safety data sheet documents; company guidance; creation, verification, locking, publication and use of Customer Calculators; measurement tools; member profile and credential records; publication records; security; support; and the other contracted functions of the Service.
Categories of data subject. Company Admins; technicians; invited users who have not yet accepted; other personnel of Customer whose details Customer records; and individuals who contact ChemCal Pro's support channel about Customer's account.
Categories of personal data.
| Category | Detail |
|---|---|
| Identity and contact | Name, email address, job title, start date, organization name |
| Authentication and session | Authentication identifier, sign-in method, session identifiers and state, sign-in and access times |
| Membership and role | Role, membership status, invited email, inviter, invitation and acceptance dates, last-seen time |
| Member profile media | Member photographs stored in private storage |
| Credential records | Credential type and identifying details as recorded, issuing body where recorded, and expiry dates used for renewal reminders |
| Credential proof documents | Images and PDF documents uploaded as evidence of a credential, including photographs of a licence card, stored in private storage |
| Authorship and review | Who created, updated, verified, locked, published or withdrew a record, and when |
| Product and document records | Product records, company guidance and notes, Label and SDS document records and their metadata, supporting files, images and links |
| Calculator records | Calculator definitions, configured values and units, source references, versions, verification, locking and publication history |
| Publication records | The document revisions present at a publication event and who published |
| Preferences | Favourites and small interface settings |
| Legal acceptance records | Document version and fingerprint, authority confirmation, accepting person's verified email and role, organization, timestamp |
| Support correspondence | Messages, attachments and troubleshooting detail relating to Customer's account |
| Technical and security | IP address, browser and device information, request and error metadata, security events, hosting and database logs, and the error/performance monitoring and error-triggered replay data described in the Privacy Notice |
Special categories / sensitive data. The Service is not designed for special-category or sensitive data. Credential records and credential proof documents can, however, contain occupational licence identifiers and images of official documents, and Customer should treat that material accordingly and limit it to what its workforce-management purpose requires. Customer must not submit health, biometric, precise-location or financial-account data, or its own end customers' records, through the Service.
Frequency. Continuous, and as initiated by Customer and its Authorized Users.
---
Annex 2 — Technical and organizational measures
These are the measures in place at the date of this DPA. They may change under Section 6.3.
Access control and tenancy
- Individual authenticated accounts; shared or generic accounts are not permitted.
- Role separation between Company Admin and technician, enforced server-side.
- Organization-level data separation applied in the database itself, not only in application code, so that one organization's records are not readable by another.
- Private storage for member photographs, credential documents, Labels, safety data sheets, product images and product documents, served through time-limited signed links rather than public URLs, with access decided by the requester's organization and role.
- An additional authentication factor is required for ChemCal Pro's own privileged platform administrators.
- One active signed-in browser context per account, so a newer sign-in displaces an older one on protected requests. This reduces concurrent misuse; it does not instantaneously revoke every already-issued token.
Application and change control
- Administrative operations run through protected server-side actions rather than client-side privilege.
- Separate development, staging and production environments, with production credentials confined to production.
- Changes are reviewed and tested before release, and production changes require explicit approval.
- Automated tests covering access control, tenancy separation, and workflow behaviour are run before release.
- Structured, allow-listed arithmetic evaluation; no execution of customer-supplied code or arbitrary expressions.
- Security response headers are applied to application responses.
Cryptography and credentials
- Encryption in transit for application traffic, and encryption at rest as provided by the underlying platform services.
- Separation of client-side and server-side credentials; privileged service credentials are never exposed to a browser.
- Backup credentials are held separately from application credentials.
Logging and evidence
- Append-only audit records for material administrative and security-relevant actions.
- Error and performance monitoring configured to exclude user identity, cookies, headers, request and response bodies, query parameters, database values and local variables, with free-text content removed before transmission.
- Publication and verification events recorded as durable evidence.
Resilience
- Provider-managed backups of the primary database, on the provider's own cycle.
- ChemCal Pro's own regular snapshot of database content and stored objects to a separate backup storage provider, with verification of the copy at creation.
- Restore procedures are documented and have been exercised.
- There is currently one independent copy with one backup storage provider, and no second off-provider copy. Point-in-time recovery is not enabled. The retention and disposal schedule for ChemCal Pro's own snapshots is being established under Section 12.5.
People
- Confidentiality obligations for personnel with access.
- Access limited to what a task requires.
---
Annex 3 — Subprocessors
The authorized subprocessors are those identified in Section 4 (Subprocessors) of the Subprocessors and Service Providers registry published on ChemCal Pro's legal pages, as amended from time to time under Section 7. Section 4 of that registry forms this Annex 3. Providers listed in Section 5 of that registry process personal data for which ChemCal Pro or the provider is the controller, and are not subprocessors for the purposes of this DPA unless and until Section 5.6 of the registry applies to them.
---